Chapter 4 Questions Flashcards
What is the CVE list?
The Common Vulnerabilities and Exposures List.
It is a dictionary of publicly known security, Vulnerabilities and Exposures
What is a Zero Day Vulnerability exploit?
A vulnerability that is unknown to the vendor. Or one where the vendor has not released a patch. If attackers discover such vulnerabilities, they are eager to exploit them.
What is a false positive?
A false positive is an alert or alarm on an event that is non-threatening, benign, or harmless.
What is a false negative?
A false negative is when am attacker is actively attacking the network, but the system does not detect it.
What is a honey pot?
A honey pot is a sweet-looking server. One that is left open and appears to have been sloppily locked down, allowing an attacker relatively easy access.
Two goals of a honey pot?
- divert attackers from the live network
- allow observation of an attacker
What is a honey net?
A group of virtual servers contained within a single physical server, and the servers within this network are honeypots. Honey nets mimic the functionality of a live network.
Passive IDS vs Active IDS?
Passive IDS just note/log the activity and send an alert to admin. Active IDS do all that AND change the environment of the network to stop and prevent the attack. An ACTIVE IDS IS BASICALLY AN IPS.
What is an Isotropic antenna?
An Isotropic antenna is a theoretical concept where an antenna has a perfect three-dimensional radiation pattern of 360 degrees vertically and horizontally.
What is a dipole antenna?
A dipole antenna is an actual antenna. Assuming it is standing vertically, it has a radiation pattern of 360 degrees horizontally and about 75 degrees vertically.
What is a Yagi/ directional antenna?
A Yagi antenna is a common type of directional antenna. The typically use a dipole, folded dipole or half wave dipole combined with additional elements such as a reflector or director elements. These additional elements focus the antenna in a single direction while also increasing the gain and refusing the radiation pattern.
What is a wireless site survey?
A wireless site survey is the process of examining the wireless environment to identify potential issues. Administrators perform a site survey while planning and developing a WLAN.
What is WPA2 encrypted with?
AES
What is 802.1x?
802.1x server is inter grated with a database of accounts and it provides port-based Authentication by requiring users and devices to authenticate before granting them access to a network. When systems connect, the 802.1x server challenges them to authenticate and prevents full network access until it receives valid credentials.
You can implement 802.1x as a RADIUS (remote Authentication dial-in user service) server.
What is a captive portal?
A captive portal is a technical solution that forces clients using web browsers to complete a specific process before it allows them to access the network.
(They tell you to acknowledge that you know what their connection may be unsafe. Check the boxes)